nerdexam
Palo_Alto_Networks

SECOPS-PRO · Question #74

You are a lead security engineer at a large enterprise, tasked with optimizing the organization's threat intelligence pipeline for maximum effectiveness against polymorphic malware and advanced…

The correct answer is B. Deploy Palo Alto Networks NGFWs with integrated WildFire cloud subscription for automated. This question focuses on building an optimal threat intelligence pipeline for advanced threats. Option B provides the most comprehensive and effective approach. Palo Alto Networks NGFWs with WildFire offer automated, real-time dynamic analysis and signature generation, directly…

Security Architecture and Design

Question

You are a lead security engineer at a large enterprise, tasked with optimizing the organization's threat intelligence pipeline for maximum effectiveness against polymorphic malware and advanced persistent threats (APTs). The current setup primarily relies on basic SIEM correlation and generic firewall rules. Your goal is to implement a solution that provides real-time, context- rich intelligence, automates detection of unknown threats, and enables proactive defense. Which of the following architectural and operational decisions would be most aligned with achieving these objectives?

Options

  • AIntegrate all network logs with VirusTotal's public API for continuous hash lookups, and manually
  • BDeploy Palo Alto Networks NGFWs with integrated WildFire cloud subscription for automated
  • CPurchase an open-source sandbox solution and develop custom Python scripts to parse its output
  • DFocus exclusively on endpoint protection platforms (EPPs) with AI-driven behavioral analysis, as
  • EImplement an extensive honeypot network to capture malware samples, then manually analyze

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    72% (26)
  • C
    14% (5)
  • D
    6% (2)
  • E
    6% (2)

Explanation

This question focuses on building an optimal threat intelligence pipeline for advanced threats. Option B provides the most comprehensive and effective approach. Palo Alto Networks NGFWs with WildFire offer automated, real-time dynamic analysis and signature generation, directly protecting the network from unknown threats, including polymorphic malware. Unit 42's premium intelligence provides the deep context on APTs, their TTPs, and campaigns, which is vital for proactive defense and understanding the adversary. Integrating these into a SIEM allows for enhanced correlation and a holistic view of the threat landscape, maximizing effectiveness. This leverages the synergistic capabilities of Palo Alto Networks' core products for a robust threat intelligence ecosystem.

Topics

#threat intelligence pipeline#WildFire#NGFW#APT defense architecture

Community Discussion

No community discussion yet for this question.

Full SECOPS-PRO Practice